2 



Tn the Claims ; 

1 . (Currently Amended) A system for external monitoring of networked 

digital file sharing to track predetermined data content, the system comprising: 

at least one surveillance element for distribution over nodes of said 
»^t.»»r V ^urh that elements associate with nodes, said surveillance elements comprising: 

search functionality for nodewise searching of said networked 

digital file sharing; eaid 

identification functionality associated v^th said search 
fimctionality for identification of said predetermined data content at a given file sharing 
system, therewith to determine whether a -said g iven file sharing system is distributing 
said predetermined data contenti.and 

an output, associated with said identification functionality, to 

produce an output indicative of said dete rmining. 

2. (Withdrawn) A system according to claim 1 , said search functionality being 
operable to carry out searching at a low level of a network protocol. 

3 . (Withdrawn) A system according to claim 1 , said search functionality being 
operable to carry out searching at a high level of a network protocol. 

4. (Withdrawn) A system according to claim 1 , said search functionality being 
operable to carry out said searching at an application level. 

5. (Original) A system according to claim 1 , wherein said surveillance element 
is a first surveillance element and said search functionality comprises fimctionality for 
operating search features of said networked digital file sharing. 

6. (Original) A system according to claim 5, wherein said identification 
functionality comprises use of a signature of said predetermined content. 
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7. (Withdrawn) A system according to claim 6, wherein said signature comprises a 
title of said predetermined content. 

8. (Withdrawn) A system according to claim 6, wherein said signature comprises a 
derivative of a title of said predetermined content. 

9. (Withdrawn) A system according to claim 6, wherein said signature comprises a 
statistical processing result carried out on said content. 

10. (Previously Presented) A system according to claim 6, wherein said signature 
comprises a result of carrying out signal processing on data of said content. 

1 1 . (Withdrawn) A system according to claim 6, wherein said signature comprises a 
description of said content. 

12. (Withdravm) A system according to claim 6, wherein said signature is a 
derivative of the description of said content. 

13. (Withdrawn) A system according to claim 1, wherein said surveillance element 
is a second surveillance element and comprises interception functionality for intercepting 
data transport on said network, and wherein said identification functionality is associated 
with said interception functionality for finding an indication of said data content within 
said intercepted data transport. 

14. (Original) A system according to claim 5, wherein said identification 
functionality comprises a signature of said predetermined content for comparison with 
data of said intercepted message to determine whether said message contains said 
evidence of said data content. 

15. (Withdrawn) A system according to claim 14, wherein said content comprises 
alphanimieric data and said signature is a derivation of said alphanumeric data. 
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16. (Withdrawn) A system according to claim 14, wherein said content comprises 
binary data and said signature comprises a derivation of said binary data, 

17. (Withdrawn) A system according to claim 16, said derivation being a hash 
function of said binary data. 

18. (Withdrawn) A system according to claim 16, said derivation being function of 
metadata of said content. 

19. (Original) A system according to claim 14, wherein said signature comprises 
a title of the said data content. 

20. (Withdrawn) A system according to claim 19, wherein said signature comprises 
a derivative of the title of the said data content. 

21. (Withdrawn) A system according to claim 19, wherein said signature comprises 
a statistical processing result carried out on said content. 

22. (Previously Presented) A system according to claim 19, wherein said signature 
comprises a result of carrying out signal processing on data of said content. 

23. (Withdrawn) A system according to claim 19, wherein said signature comprises 
a description of said content. 

24. (Original) A system according to claim 19, wherein said signature comprises 
a derivative of the description of said content. 

25. (Withdrawn) A system according to claim 1, wherein said surveillance element 
further comprises input/output functionality for receiving commands from said system 
and sending results of said search. 
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26. (Withdrawn) A system according to claim 25, further comprising a co- 
ordination element for interacting with said distributed input/output fiinctionality to 
control deployment of said surveillance elements over said network and to monitor 
results from a plurality of said surveillance elements. 

27. (Withdrawn) A system according to claim 26, said co-ordination element 
further being operable to interact with reaction elements by providing said reaction 
elements with details of locations of said predetermined content obtained from said 
surveillance elements, thereby to prompt said reaction elements to react against said 
locations. 

28. (Withdrawn) A system according to claim 1 , wherein said file sharing comprises 
a document exchange system and said surveillance element fiirther comprises 
functionality for representing itself as a host server for said system, thereby to obtain data 
of dociunents on said system for said search functionality. 

29. (Withdrawn) A system according to claim 1 , comprising: 

at least two first surveillance elements, each first surveillance element 
comprising fimctionality for operating search features of said networked digital file 
sharing. 

at least two second surveillance elements, each said second surveillance 
element comprising interception fimctionality for intercepting messaging on said 
network, and wherein said identification fimctionality is associated with said interception 
fimctionality for identifying evidences of said data content within said intercepted 
messages, and 

at least one control element for deploying said surveillance elements 
around said network and obtaining search results from said surveillance elements. 
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30. (Withdrawn) A system according to claim 22, wherein said surveillance element 
is a first surveillance element and said search functionality comprises functionality for 
operating search features of said networked digital file sharing. 

3 1 . (Withdrawn) A system according to claim 23, wherein said identification input 
functionality is operable to receive input from a comparator associated with a signature 
holder for holding a signature of said predetermined content, said comparator being 
operable to compare said content against said signature thereby to indicate to said input 
functionality the presence of said content. 

32. (Withdrawn) A system according to claim 24, wherein said signature comprises 
a title of said predetermined content. 

33. (Withdrawn) A system according to claim 24, wherein said signature is a 
derivative of a title of said predetermined content. 

34. (Withdrawn) A system according to claim 24, wherein said signature comprises 
a statistical processing result carried out on said content. 

35. (Previously Presented) A system according to claim 24, wherein said 
signature comprises a resuU of signal processing carried out on data of said content. 

36. (Withdrawn) A system according to claim 24, wherein said signature comprises 
a description of said content. 

37. (Withdrawn) A system according to claim 24, wherein said signature comprises 
a derivative of a description of said content. 

38. (Withdrawn) A system according to claim 22, wherein said surveillance element 
is a second surveillance element and comprises interception functionality for intercepting 
messaging on said network, and wherein said identification functionality is associated 
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with said interception functionality for identifying evidences of said data content within 
said intercepted messages, 

39. (Withdrawn) A system according to claim 23, wherein said search functionality 
fiirther comprises input/output functionality for receiving commands from said system 
and sending results of said search. 

40. (Withdrawn) A system according to claim 3 1 , further comprising a co- 
ordination element for interacting with said distributed input/output functionality to 
control deployment of said surveillance elements over said network and to monitor 
results firom a plurality of said surveillance elements, said co-ordination element further 
being operable to interact Math a plurality of attack elements by providing said attack 
elements with details of locations of said predetermined content obtained from said 
surveillance elements, thereby to prompt said attack elements to attack said locations. 

41 . (Withdrawn) A system according to claim 22, wherein said file sharing 
comprises a document exchange system and said surveillance element further comprises 
functionality for representing itself as a host server for said system, thereby to obtain data 
of said file sharing for said search functionality. 

42. (Withdrawn) A system according to claim 33, said identification functionality 
being operable to identify items in said document exchange system comprising said 
predetermined content. 

43. (Withdrawn) A system according to claim 42, further comprising an attack 
element, said attack element comprising functionality to send to said system a delete 
command to delete said item throughout said system. 

44. (Withdrawn) A system according to claim 22, further comprising an attack 
element and wherein said attack element comprises repetitive output functionality for 
repeatedly sending response requests to said file sharing system. 
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45. (Withdrawn) A system according to claim 36, wherein said response request 
comprises a download request. 

46. (Withdrawn) A system according to claim 37, operable to co-ordinate response 
requests between a plurality of attack elements distributed over said network. 

47. (Withdrawn) A system according to claim 38, operable to co-ordinate download 
requests between a plurality of attack elements distributed over said network. 

48. (Withdrawn) A system according to claim 22, wherein said surveillance agent is 
a third surveillance element, comprising network protocol scan functionality operable to 
intercept and analyze network communication items of a predetermined network traffic, 
thereby to find protected content in transport. 

49. (Withdrawn) A system according to claim 22, comprising at least one attack 
element wherein said attack functionality is operable to utilize features of said file sharing 
in said attack 

50. (Withdrawn) A system according to claim 22, comprising at least one attack 
element wherein said attack fimctionality comprises transport interference fimctionality 
for interfering with messaging over said network. 

5 1 . (Withdrawn) A system according to claim 42, wherein said transport 
interference functionality comprises exchange fimctionality for exchanging said 
predetermined message content in said messaging with other message content. 



52. (Withdrawn) A system according to claim .3 1 , comprising: 

at least two first surveillance elements, each first search element comprising 
fimctionality for operating search features of said networked digital file sharing. 
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at least two second sxirveillance elements, each said second surveillance 
element comprising interception fimctionality for intercepting messaging on said 
network, and wherein said identification fimctionality is associated with said interception 
fimctionality for identifying evidences of said data content within said intercepted 
messages, 

at least two of said attack elements, and 

at least one control element for distributing said surveillance and attack 
elements around said network, obtaining surveillance results fi-om said surveillance 
elements, and coordinating activity of said attack elements to carry out a coordinated 
multiple point attack on said file sharing system. 

53. (Withdrawn) A system for extemal monitoring and control of networked 

digital file sharing to track predetermined data content and limit distribution thereof, the 

system comprising: 

at least one surveillance element for distribution over said network, said 

surveillance element comprising: 

surveillance fimctionality for searching said digital file sharing 

and 

identification input fimctionality associated with said search 
fimctionality for receiving an indication of the presence of said predetermined content, 
and 

at least one attack element, comprising: 

input fimctionality for receiving identification data of a file sharing 
system foxmd to be distributing said predetermined content, and 

attack fimctionality for applying an attack to said file sharing 
system to reduce said file sharing system's ability to distribute said predetermined data 
content. . 

54. (Withdrawn) A network extemal content distribution control system comprising 
network content identification fimctionality for identifying predetermined content 
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distributed over a digital file sharing network, said network comprising a plurality of 
nodes, and 

network attack functionality for applying an attack over said digital file sharing 
network, said attack being directable to reduce the ability of the network to distribute said 
identified content. 

55. (Withdrawn) A system according to claim 54, at least one of said nodes being 
identified to have said predetermined content, and at least one of said nodes being 
identified as a distribution node of said network, said attack being directable at said 
distribution node. 

56. (Withdrawn) A network extemal content distribution control system comprising 
at least one surveillance unit for exploring a network to determine at least one of a 
presence and a distribution pattern of predetermined content and for reporting said 
determination for remote analysis. 

57. (Withdrawn) A network scanning element for use in a network extemal content 
distribution control system, said scanning element being operable to scan at least a 
portion of a network suspected of distributing predetermined content by connecting to 
available ports in the network portion, via said port connections to determine the presence 
of network nodes participating in said distribution. 

58. (Withdrawn) A method of externally scanning a distributed network comprising 
a plurality of nodes, to search for predetermined content available for distribution fi-om 
said nodes, the method comprising: 

distributing at least one surveillance element to said network, said 

surveillance element comprising: 

search fiinctionality for nodewise searching of said networked 
digital file sharing and identification fimctionality associated with said search 
fimctionality for identification of said predetermined data content, therewith to determine 
whether a given file sharing system is distributing said predetermined data content. 



